CVE-2024-47771: Element Desktop vulnerable to potential exposure of access token via authenticated media
Element Desktop is a Matrix client for desktop platforms. Element Desktop versions 1.11.70 through 1.11.80 contain a vulnerability which can, under specially crafted conditions, lead to the access token becoming exposed to third parties. At least one vector has been identified internally, involving malicious widgets, but other vectors may exist. Users are strongly advised to upgrade to version 1.11.81 to remediate the issue. As a workaround, avoid granting permissions to untrusted widgets.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-47771?
CVE-2024-47771 has been categorized with a severity level that indicates a risk of exposure for access tokens under specific conditions.
How do I fix CVE-2024-47771?
To fix CVE-2024-47771, update Element Desktop to version 1.11.81 or later immediately.
What versions of Element Desktop are affected by CVE-2024-47771?
Element Desktop versions 1.11.70 through 1.11.80 are affected by CVE-2024-47771.
What are the potential consequences of CVE-2024-47771?
The potential consequences of CVE-2024-47771 include the exposure of access tokens to unauthorized third parties.
Is there a workaround for CVE-2024-47771 if I cannot update immediately?
There are no documented workarounds for CVE-2024-47771, so updating to the latest version is recommended.